Quantcast
Channel: Directory Services forum
Viewing all 31638 articles
Browse latest View live

Window Server 2012 Error: MMC has detected an error in a snap-in. It is recommended that you shut down and restart MMC.

$
0
0

When I try to add a group policy for Windows Server 2012 R2 under the Domain Controller=>Default Domain Controller Policy, the pop up window works fine. When I try to go to Computer Configuration Policy=>Windows Settings=>Security Settings, as soon as I hit the Security Setting tab=> I get the following error for the Wired Network Policy Management

"MMC has detected an error in a snap-in. It is recommended that you shut down and restart MMC."


DNS Error?

$
0
0

Looking for some help here.  Mentally fried after trying to figure this out.

Overview of our servers

PDC - purple2

ops2 - DC\DHCP

NTMX2 - old mail server, DC and backup for AD

Below is the results of the "DCDIAG" command on the Server "Ops2"

Directory Server Diagnosis

Performing initial setup:
   Trying to find home server...
   Home Server = ops2
   The GUID based DNS Name resolved to several IPs (::1, 172.16.10.8), but not all were pingable. Replication and other operations may fail if a
   non-pingable IP is chosen. The first pingable IP is 172.16.10.8.
   [ops2] Directory Binding Error 5:
   Access is denied.
   This may limit some of the tests that can be performed.
   * Identified AD Forest.
   Done gathering initial info.

Doing initial required tests

   Testing server: Central\OPS2
      Starting test: Connectivity
         ......................... OPS2 passed test Connectivity

Doing primary tests

   Testing server: Central\OPS2
      Starting test: Advertising
         ......................... OPS2 passed test Advertising
      Starting test: FrsEvent
         ......................... OPS2 passed test FrsEvent
      Starting test: DFSREvent
         The event log DFS Replication on server ops2.wallenpaupack.org could not be queried, error 0x5 "Access is denied."
         ......................... OPS2 failed test DFSREvent
      Starting test: SysVolCheck
         ......................... OPS2 passed test SysVolCheck
      Starting test: KccEvent
         The event log Directory Service on server ops2.wallenpaupack.org could not be queried, error 0x5 "Access is denied."
         ......................... OPS2 failed test KccEvent
      Starting test: KnowsOfRoleHolders
         [PURPLE2] DsBindWithSpnEx() failed with error -2146893022,
         The target principal name is incorrect..
         Warning: PURPLE2 is the Schema Owner, but is not responding to DS RPC Bind.
         [PURPLE2] LDAP bind failed with error 8341,
         A directory service error has occurred..
         Warning: PURPLE2 is the Schema Owner, but is not responding to LDAP Bind.
         Warning: PURPLE2 is the Domain Owner, but is not responding to DS RPC Bind.
         Warning: PURPLE2 is the Domain Owner, but is not responding to LDAP Bind.
         Warning: PURPLE2 is the PDC Owner, but is not responding to DS RPC Bind.
         Warning: PURPLE2 is the PDC Owner, but is not responding to LDAP Bind.
         Warning: PURPLE2 is the Rid Owner, but is not responding to DS RPC Bind.
         Warning: PURPLE2 is the Rid Owner, but is not responding to LDAP Bind.
         Warning: PURPLE2 is the Infrastructure Update Owner, but is not responding to DS RPC Bind.
         Warning: PURPLE2 is the Infrastructure Update Owner, but is not responding to LDAP Bind.
         ......................... OPS2 failed test KnowsOfRoleHolders
      Starting test: MachineAccount
         ......................... OPS2 passed test MachineAccount
      Starting test: NCSecDesc
         ......................... OPS2 passed test NCSecDesc
      Starting test: NetLogons
         ......................... OPS2 passed test NetLogons
      Starting test: ObjectsReplicated
         ......................... OPS2 passed test ObjectsReplicated
      Starting test: Replications
         [Replications Check,OPS2] A recent replication attempt failed:
            From PURPLE2 to OPS2
            Naming Context: DC=ForestDnsZones,DC=wallenpaupack,DC=org
            The replication generated an error (1256):
            The remote system is not available. For information about network troubleshooting, see Windows Help.
            The failure occurred at 2019-07-09 15:57:41.
            The last success occurred at 2019-05-23 11:35:10.
            128 failures have occurred since the last success.
         [Replications Check,OPS2] A recent replication attempt failed:
            From PURPLE2 to OPS2
            Naming Context: DC=DomainDnsZones,DC=wallenpaupack,DC=org
            The replication generated an error (1256):
            The remote system is not available. For information about network troubleshooting, see Windows Help.
            The failure occurred at 2019-07-09 15:57:41.
            The last success occurred at 2019-05-23 11:35:10.
            128 failures have occurred since the last success.
         [Replications Check,OPS2] A recent replication attempt failed:
            From PURPLE2 to OPS2
            Naming Context: CN=Schema,CN=Configuration,DC=wallenpaupack,DC=org
            The replication generated an error (-2146893022):
            The target principal name is incorrect.
            The failure occurred at 2019-07-09 15:57:41.
            The last success occurred at 2019-05-23 11:35:10.
            129 failures have occurred since the last success.
         [Replications Check,OPS2] A recent replication attempt failed:
            From PURPLE2 to OPS2
            Naming Context: CN=Configuration,DC=wallenpaupack,DC=org
            The replication generated an error (-2146893022):
            The target principal name is incorrect.
            The failure occurred at 2019-07-09 15:57:41.
            The last success occurred at 2019-05-23 11:35:10.
            128 failures have occurred since the last success.
         [Replications Check,OPS2] A recent replication attempt failed:
            From PURPLE2 to OPS2
            Naming Context: DC=wallenpaupack,DC=org
            The replication generated an error (-2146893022):
            The target principal name is incorrect.
            The failure occurred at 2019-07-09 15:57:41.
            The last success occurred at 2019-05-23 11:35:09.
            128 failures have occurred since the last success.
         ......................... OPS2 failed test Replications
      Starting test: RidManager
         ......................... OPS2 failed test RidManager
      Starting test: Services
         ......................... OPS2 passed test Services
      Starting test: SystemLog
         The event log System on server ops2.wallenpaupack.org could not be queried, error 0x5 "Access is denied."
         ......................... OPS2 failed test SystemLog
      Starting test: VerifyReferences
         ......................... OPS2 passed test VerifyReferences


   Running partition tests on : ForestDnsZones
      Starting test: CheckSDRefDom
         ......................... ForestDnsZones passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... ForestDnsZones passed test CrossRefValidation

   Running partition tests on : DomainDnsZones
      Starting test: CheckSDRefDom
         ......................... DomainDnsZones passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... DomainDnsZones passed test CrossRefValidation

   Running partition tests on : Schema
      Starting test: CheckSDRefDom
         ......................... Schema passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... Schema passed test CrossRefValidation

   Running partition tests on : Configuration
      Starting test: CheckSDRefDom
         ......................... Configuration passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... Configuration passed test CrossRefValidation

   Running partition tests on : wallenpaupack
      Starting test: CheckSDRefDom
         ......................... wallenpaupack passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... wallenpaupack passed test CrossRefValidation

   Running enterprise tests on : wallenpaupack.org
      Starting test: LocatorCheck
         ......................... wallenpaupack.org passed test LocatorCheck
      Starting test: Intersite
         ......................... wallenpaupack.org passed test Intersite

Desktop Icons dissapearing form AD users shared Desktop

$
0
0

Hello! I am quite new to AD. I got introduced to an already set up domain (the IT guy who set it up, left) controller and we have been having issues with some users under a certain GPO.

We are using folder forwarding for a group of users so they share the same desktop icons. Sometimes, some icons disappear on their own, then they come back. Nobody is deleting anything from their desktop so I don't know what this could be.

Can it be the connection to the server lagging or something; or maybe a virus?

Thanks in advance.



Domain Controllers unresponsive - network issue

$
0
0
We have recently faced a very strange issue that all of our windows 2008 r2 domain controllers were not authenticating to clients. Upon investigating we found that we can not ping any of the domain controller and getting request time from all domain controllers. We have 2 sites. Site A has 1 physical DC with all fsmo roles and 1 virtual DC running on Hyper-V. Site B have 2 DCs running on hyper-V host. During this issue we were able to ping other VMs running on same host. All 3 DC vm and 1 physical DC wasnt responding. We rebooted physical and virtual both domain controllers but issue reappeared after 3 to 4 minutes. Then we rebooted them again but before that we unplugged ethernet cable from physical server and disabled virtual NIC from VM. After that all were working perfectly. We couldnt find that cause that why it happened? We are using trendmicro endpoint security. Scanned all 4 DCs but it couldnt find anything. Event logs were showing errors of ADWS 1206 and other directory services and DNS errors. How can we find the root cause of this issue and avaoid from this happening again? 

Restricting Access to Important PC in Windows 10 Pro

$
0
0

I have a problem where any Domain Admin can backdoor into another PC on the domain via \\PCNAME\C$

Is there a way to block this type of entry on a PC for security purposes?  Our Directors are requesting that NOBODY can access their system without their knowledge but I have not found a way to block this.  Our IT Engineering group are all Domain Admins.

Enabling proxy settings via GPO

$
0
0

Hello all,

I have been struggling with getting our proxy settings to filter down to user machines over the past week. I have created a new GPO solely for this purpose using the internet options> connections > LAN settings as well as using reg keys to try and enforce it. 

However upon gpudating the expected settings do not show in the user machines internet options. When running gpresult /z I can see the policy is not being blocked and the user is in the correct OU andsecurity groups. If anyone has any pointers that would be great!

DNS Server in DMZ

$
0
0
Hi we are going to create DNS Servers in DMZ. Should we install ADDS on it or not? If we install ADDS, should it be RODC or not. Also if we do not install ADDS on it, what should be the way forward.

PRIMARY DOMAIN CONTROLLER

$
0
0

we have this situation in our IT Infrastructure. 

we have two domain controllers DC01 and DC02 both are windows server 2008R2 sp2.


DC01(Primäre Domain)
*Domain Controller (DC)
*DNS
*DHCP
*File Server
*Print server

DC02(Secondary Domain)
*Domain Controller (DC)
*DNS
*DHCP
*File Server
*Print server

we have install new DC03 Server with OS Window Server 2012 R2

DC03
*Domain Controller (DC)
*DNS
*DHCP
*File Server
*Print server


We want DC03 (Primary Domain) to become Directory Domain and DC01(Secondary Domain)

Can you help us what steps do we need to make...
what are the steps for change Primary Domain controller with another Server "DC03"


Can you raise functional level incrementally?

$
0
0

We're running at 2008 R2 FL on 2008 R2 DCs. We'd like to migrate to 2016 FL on 2019 DCs.


Is it possible to add 2019 DCs, demote the 2008 DCs, then raise the FL incrementally 2008 R2 -> 2012 R2 -> 2016? Or does that require stepping up the server version as well? We're trying to do as few server migrations as possible.

Unlocking Windows 10 PC takes too long

$
0
0
Hi we have an strange issue. we have 2 2012 r2 Dc and one 2019 DC , FSMO roles are on 2019 DC. We configure that 10 minutes after no input pcs are locked out. The clients report that when they wanna unlock their pc it wait welcome screen almost 1 minute and then unlocks pc. 

Clear Security Logs by error

$
0
0

Hello ,

In our AD 2016 , i was removed accidently  the  oldest security logs  and the DC know is not backupped .is there a way to restore the security logs ?

Regards

user profiles roaming deployment

$
0
0

hi all ,

im new here and im planing to deploy roaming profiles using GPO and i want to ask :

after i read the Microsoft roaming doc regarding to  deploy roaming to computer i wanna ask about msDS-PrimaryComputer attribute , my company have many user divided between department and works in shift's my question is can i assign a distribution group in  msDS-PrimaryComputer  and for many computer : like in first computer i assign HR group in primary computer attribute and for the second computer can i also assign the same group (HR group ) .

hope i deliver the the idea :) 


2016 - Read Only Domain Controller Deleted!!

$
0
0

A problematic domain controller was shutdown to resolve the issue and then deleted from AD, DNS, Sites and Services.  I did not delete it cos I would have dcpromo to remove it if anything but everything seems to be working fine after.

Now I ran repadmin /syncall/ AdeP from the the DC that holds all the roles and all looks good no errors seen.

I am trying to attempt to remove the metadata and meeting this error:

C:\>ntdsutil
ntdsutil: metadata cleanup
metadata cleanup: connections
server connections: connect to server DC-02
Binding to DC-02 ...
DsBindWithSpnExW error 0x6ba(The RPC server is unavailable.)
ldap_search for attribute supportedCapabilities failed with 0x59(89 (Parameter Error).
)
server connections:

How can I remove the metadata?  Any links to step by step which I can use and remove this DC-02 via ADSIedit?

Much appreciated!




Promote Azure compute resource to DC in on premise AD

$
0
0

I have an Azure compute resource running Windows Server 2016.  AADDS is already configured, and the Azure server is now a member of the on premise AD.  I need to promote the Azure server to DC in the on premise AD.  The Azure server is not listed as a computer object in the on premise AD, and the server is not listed as a device in the Azure tenant.  Is that a problem, and if so how can both those issues be resolved?  

What is the process for promoting the Azure server to DC in the on premise AD?  Thank you.

Office Online server not work with IIS ARR

$
0
0

Hi Support,

We have an office online server and it works on internal network. However, it does not works when a user tries to access it from external network.

We are using Windows Server 2016 IIS ARR to publish exchange 2016 and also Office online server. Exchange services (owa, autodiscover, activesync, etc.) works fine, but the office online services failed.  

The rules setting is regular expression ((?:^en-us/|^hosting/|^m/|^o/|^oh/|^op/|^p/|^we/|^wv/|^x/).*). After open the documents, it will show this error:

 

The testing link https://oos.xxxxx.com/hosting/discovery can access normally.

Any ideas?

Best Regards

Chong 

 


Andy Chong


NETLOGON.LOG stopped reporting NO_CLIENT_SITE messages

$
0
0

We have a 2016 Forest/Domain with 4 domain controllers all running Windows 2016. 

Daily all four domain controllers have been reporting NO_CLIENT_SITE messages both within the NETLOGON.LOG/NETLOGON.BAK and System log with EVENTID 5807

Up until last Wednesday 3rd July where they've all stopped doing it. 

The NETLOGON.LOG/NETLOGON.BAK files all have different time stamps varying from 16:15 to 19:12 on the DC's but that's it the messages stop. In event viewer no more reports of ID 5807 either. 

I know that we still have missing subnets, as I only got asked to take a look on Friday and have created 94 missing subnets with a further 18 still to do. At this point I paused to go and refresh the data I had and noticed it was at the 3rd timestamp. 

I've tried:

  • Increasing the log file size available.
  •  Rebooted all of the DC's (three of which were waiting to apply the June rollup patch, the fourth installed it on the 3rd)
  • Enabled verbose NETLOGON.LOG logging and it was writing to the log but not the NO_CLIENT_SITE messages. 

Any ideas on how I can re-instate these messages? 

Mark

Migration from RFS to DFSr issue

$
0
0

Dear All,

Greetings,

After runining  Dfsrmig /setglobalstate 1

The following is "Dfsrmig /getmigrationstate" results:

and below is "Dfsrmig /getglobalstate"

kindly, need your help to solve the issue.

Thanks in advance.

Regards,

Faisal

NO Matter What 2way domain trust not working !!

$
0
0

I merging two educational establishment Domains 

I have 2 domains    d.edu.sa  and k.edu.sa  each is separate forest . 

I have establish 2way forest trust , done all necessary DNS forwarding etc  , nslook up working both ways with FQDN and Netbios 

I can browse objects from D domain in K domain , but when select I get : 

the active directory domain controller required to find the selected objects in the following domains are not available :

d.edu.sa
ensure the active directory domain controller are available and try agian

I have query ports 389 every thing seems to be in place ,what on earth could be the problem 

Note : when creatin trust I had to do it from each domain 

I have been chasing my tail for two weeks now and almost try everything in tech blog I came across ..  

Can any one help , please note that I have done all home work including firewall , network between 2 are fine .what on earth could be the issue !!

Need to Raise domain and Forest functional level.

$
0
0

Hi

We have Windows 2008R2 Active directory server, 2008R2 Additonal DC , RODC and 2008R2 Terminal servers in our office.

We would plan to Migrate to 2016 server version and when we check our Active directory server functional level and found as below



Also the Forest functional level also Windows server 2003 only.

Now we would want to raise both Domain and Forest functional level to 2008R2. Please advice me how to do that.

Also i would like to know Migration to 2016 version is after doing this better.

Thanks

Krishna

Changing password option is greyed out after joining the machine to the domain

$
0
0

Hi

I want to allow my users to change the password once they logged into the server.

The changing password option is available when I log into the machine using a local account but after I join the machine to the domain and log in with a domain user, the password change option is greyed out.

It is a new Active Directory I built recently and there is no group policies applied.

I want to know how to enable the password change option for the users.

Option greyed out:

Viewing all 31638 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>